poster-hero
Pass
Audited by Gen Agent Trust Hub on Aug 2, 2026
Risk Level: SAFEEXTERNAL_DOWNLOADSCOMMAND_EXECUTIONPROMPT_INJECTION
Full Analysis
- [EXTERNAL_DOWNLOADS]: The skill's example HTML fetches CSS from 'cdn.tailwindcss.com' and typography from 'fonts.googleapis.com'. These are well-known services used for web styling and font delivery.
- [COMMAND_EXECUTION]: The example poster design (in 'example.html') includes an illustrative command '$ pnpm dlx html-anything'. This is static text used for visual presentation and does not instruct the agent to execute shell commands.
- [PROMPT_INJECTION]: The skill exhibits an indirect prompt injection surface:
- Ingestion points: User-provided marketing content and data specified in the 'example_prompt' in 'SKILL.md'.
- Boundary markers: Absent; there are no delimiters or instructions to ignore potential commands embedded in user data.
- Capability inventory: HTML, CSS, and SVG generation for visual layout rendering.
- Sanitization: Absent; the skill does not specify filtering or escaping of user input before rendering into the poster template.
Audit Metadata